Background
Wired journalist Mat Honan was recently hacked hard. Hackers gained access to his Apple iCloud, Twitter and Google accounts. They posted some vile comments via his Twitter, deleted his Google account, and wiped his iPhone, iPad and MacBook Air. His MacBook air was the only place he had more than a year’s worth of photos, covering the entire lifespan of his daughter. (He's since recovered his data, at a cost of about $1500.) Really, he was lucky in that they did this for the “lulz”, not to gain access to a bank account or steal his identity.There is no such thing as perfect security when online, but you can take steps to be more secure. Before looking at solutions, let's consider the issues.
Authenticating yourself involves providing evidence that you are you. You can prove who you are through:
- something you are (e.g. a finger print)
- something you know (e.g. a password)
- something you have (e.g. a mobile phone).
I've spent a fair bit of time getting secure as reasonable. The main ways of doing this are:
- Using strong passwords
- Two factor authentication
What to not do
Most people use terrible passwords. The most common passwords are:- password
- 123456
- 12345678
- 1234
- qwerty
- 12345
- dragon
- pussy
- baseball
- football
- letmein
- monkey
- 696969
- abc123
- mustang
- michael
- shadow
- master
- jennifer
- 111111
- 2000
- jordan
- superman
- harley
- 1234567
Some basics of things you shouldn't do. Do not use:
- personal information in your password that someone could work out
- dictionary words, or geographical or biographical names
- a password that is the same as your account information.
- The average Web user maintains 25 separate accounts but uses just 6.5 passwords to protect them.
- In the past year alone more than 100 million passwords have been published online.
- 8.2 billion average passwords combinations per second are able to be tried by a PC running a single AMD Radeon HD7970 GPU.
- Adding numbers or non-alphanumeric characters such as "!!!" to them, usually at the end, but sometimes at the beginning.
- "Mangling" — transforming words such as "super" or "princess" into "sup34" and "prince$$".
- Mirror imaging — "book" becomes "bookkoob" and "password" becomes "passworddrowssap".
- Appending a date of birth or similar to a name — Julia1984.
How to create a strong password
The fundamentals of making a password strong are:- A bigger set of characters: numbers only (10 characters), numbers + lowercase + uppercase letters (10 + 26 + 26 = 62 characters), all the characters on your keyboard (92).
- The longer the better. Longer means exponentially more possible combinations an attacker has to try. A four character password would take about 0.0004 seconds to crack. A 10 character one would take about a year.
- Increase entropy. Use random characters for your passwords.